Dinis Cruz
This site is my position on open source — what it is for, how to practise it, and the history that supports it. It is written from the experience of building, open-sourcing and running security software and companies, and it is the strategy those companies actually run on: everything they ship is open source, and so are their investor materials.
The record
| Role | What it involved |
|---|---|
| Founder, sgit.ai | Encrypted vaults with git semantics — clone, commit, branch and merge files encrypted before they leave your machine — under Apache-2.0, and the network of nineteen sites of which this is one. Each site publishes its argument before its implementation, so the commitments are checkable. |
| Founder, sgraph.ai | Where the strategy turns into revenue: the commercial home of SG/Send, the secure file-sharing service built on the open-source sgit layer, and the place that sells access to SG/Vaults — hosted sgit vaults. The code stays Apache-2.0; what is sold is the running, maintained, certified service, which is exactly where this site says the commercial line belongs. |
| Founder, MyFeeds.ai | Role-aware cybersecurity briefings built on semantic knowledge graphs — CISO, engineer and board views of the same news, with source attribution. 100% open source, serverless, no vendor lock-in. The seed pitch, use of funds and unit economics are published in the open. |
| Founder, The Cyber Boardroom | An AI-powered platform for the conversation between technical security teams and the board — bridging the two with knowledge-graph technology. Apache-2.0, with the community edition, the website and the automation in public repositories. |
| Founder, RiskMandate.ai | The business risk layer for autonomous systems. The newest of the startups, alongside VoiceDebrief. |
| Founder, VoiceDebrief.ai | Voice recordings into transcripts and debriefs, entirely in the browser — no account, and nothing uploaded to a server. The "ask for keys at run time, store nothing" habit from the founders' page, shipped as a product. |
| Former OWASP Board member | And organiser of the OWASP Summits — Lisbon 2011 and Woburn 2017, the working-session format with "no spectators, only participants" that the Open Security Summit series went on to build on. Current open-source work still ships under the owasp-sbot organisation, with MGraph-DB publicly credited to the OWASP community. |
| Creator, the O2 Platform | The OWASP static-analysis engine of 2010–2012, and the first of a line of open-source tooling that continues in the osbot-* and mgraph-* families, memory_fs, Issues-FS and sgit-ai — all Apache-2.0, all on PyPI. |
Built in the open, including the parts most companies keep closed
The argument on this site is that open source is a strategy rather than a charity, and the strongest evidence I can offer for it is that I run companies on it. That extends past the code:
- The code is Apache-2.0. The working documents — roughly 1,100 of them — are CC BY 4.0. The published essays at docs.diniscruz.ai are CC BY 4.0 as well — decided on 6 September 2026, after that repository's licence file was found to say CC0; the file follows. Two licences, three layers, and what each is for →
- The investor materials are public. MyFeeds.ai's investor relations site, its source repository, and The Cyber Boardroom's investment repository are on GitHub rather than behind a data room. If technology is not the moat, neither is the pitch deck.
- This site's own source — every page as markdown, the build tooling, the briefs it was written from — is in the repository, and the estate is run through its own stress test with the result published.
- The advice is published too. Owning the code, or opening it is the reasoning from a strategy session with another founder, released CC BY so that it applies to every founder asking the same question.
Interests declared
I run companies whose strategy this is, and which sell maintenance, quality and certification rather than code — the market this site describes is one I intend to be in. Read the argument knowing that. Two things are built in to keep it honest:
- The history is checkable without trusting me. Every claim in the six corrections and the timeline carries its source and date, and several of them cut against the story that would flatter the argument. The numbers this site declines to publish are the ones that would have helped it.
- The tool works without me. The stress test is answerable from public artefacts and runs entirely in your browser; nothing is sent anywhere. And rather than publish verdicts on named competitors, it is run on my own estate, in public, with what each leg would take to change.
Reach me, or correct me
↗ LinkedIn is the fastest route. Corrections and requests for this site are tracked in the open on the comms board, and the repository takes issues and pull requests. If you find something wrong here, I would rather know.